Understanding Internet of Things Malware by Analyzing Endpoints in their Static Artifacts

03/26/2021
by   Afsah Anwar, et al.
0

The lack of security measures among the Internet of Things (IoT) devices and their persistent online connection gives adversaries a prime opportunity to target them or even abuse them as intermediary targets in larger attacks such as distributed denial-of-service (DDoS) campaigns. In this paper, we analyze IoT malware and focus on the endpoints reachable on the public Internet, that play an essential part in the IoT malware ecosystem. Namely, we analyze endpoints acting as dropzones and their targets to gain insights into the underlying dynamics in this ecosystem, such as the affinity between the dropzones and their target IP addresses, and the different patterns among endpoints. Towards this goal, we reverse-engineer 2,423 IoT malware samples and extract strings from them to obtain IP addresses. We further gather information about these endpoints from public Internet-wide scanners, such as Shodan and Censys. For the masked IP addresses, we examine the Classless Inter-Domain Routing (CIDR) networks accumulating to more than 100 million (78.2 active public IPv4 addresses) endpoints. Our investigation from four different perspectives provides profound insights into the role of endpoints in IoT malware attacks, which deepens our understanding of IoT malware ecosystems and can assist future defenses.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/10/2019

Analyzing Endpoints in the Internet of Things Malware

The lack of security measures in the Internet of Things (IoT) devices an...
research
02/11/2018

Lightweight Classification of IoT Malware based on Image Recognition

The Internet of Things (IoT) is an extension of the traditional Internet...
research
10/29/2021

Evaluation of an Anomaly Detector for Routers using Parameterizable Malware in an IoT Ecosystem

This work explores the evaluation of a machine learning anomaly detector...
research
07/19/2023

Analyzing IoT Hosts in the IPv6 Internet

Users and businesses are increasingly deploying Internet of Things (IoT)...
research
02/27/2023

Nautilus: A Framework for Cross-Layer Cartography of Submarine Cables and IP Links

Submarine cables constitute the backbone of the Internet. However, these...
research
07/22/2020

An SDN-IoT-based Framework for Future Smart Cities: Addressing Perspective

In this Chapter, a software-defined network (SDN)-based framework for fu...
research
09/30/2021

RFID Exploitation and Countermeasures

Radio Frequency Identification (RFID) systems are among the most widespr...

Please sign up or login with your details

Forgot password? Click here to reset